CVE-2017-11687: Zohocorp ManageEngine Eventlog Analyzer

Medium severity, CVSS 6.1. EPSS: 1.3% chance of exploitation in the next 30 days.

Multiple Persistent cross-site scripting (XSS) vulnerabilities in Event log parsing and Display functions in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML via syslog.

Affected products

  • Zohocorp ManageEngine Eventlog Analyzer: version 11.4 only; version 11.5 only

Published 2017-07-27. Last modified 2026-06-17.